Privacy Policy
Effective / Last Updated: July 26, 2026
This Privacy Policy is published in accordance with, and in compliance with:
• The Information Technology Act, 2000 (Section 43A and related provisions)
• The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules")
• The Digital Personal Data Protection Act, 2023 ("DPDP Act") and rules made thereunder, to the extent notified and applicable
• The Consumer Protection (E-Commerce) Rules, 2020, to the extent applicable to online sellers
• Applicable directions issued by the Indian Computer Emergency Response Team ("CERT-In")
Magic Print Global LLP ("Magic Print," "Company," "we," "us," or "our"), a Limited Liability Partnership operating the website www.magicprint.in (the "Website" or "Platform"), is the Data Fiduciary (under the DPDP Act) and Body Corporate (under the IT Act) in respect of the personal data described in this Policy.
This Policy applies to all visitors, users, customers, and vendors who access the Website or transact with us. By using the Website, submitting your information, or placing an order, you consent to the collection, use, storage, and disclosure of your information as described here.
1. Definitions
• "Personal Data" means any data about an individual who is identifiable by or in relation to such data (DPDP Act, Sec. 2(t)).
• "Sensitive Personal Data or Information (SPDI)" as defined under the SPDI Rules, 2011, includes financial information (bank account/card/payment instrument details), and any detail relating to the above as provided to us for processing.
• "Data Principal" means the individual to whom the personal data relates, i.e., you.
• "Data Fiduciary" means Magic Print Global LLP, which determines the purpose and means of processing your personal data.
• "Processing" includes collection, recording, organisation, storage, use, sharing, and deletion of personal data.
• "Consent Manager" means a person/entity registered with the Data Protection Board who enables a Data Principal to manage consent, where applicable.
2. Information We Collect
2.1 Information You Provide Directly
• Identity data — full name, username
• Contact data — email address, phone number, billing/shipping address
• Order & customization data — product selections, custom text/logos/photos/artwork uploaded for UV printing or personalization
• Business/corporate data — company name, GSTIN, PAN (for invoicing), designation, official email
• Financial data — billing details and payment confirmation status (full card/UPI/bank credentials are collected and processed directly by our RBI-regulated payment gateway partners, and are NOT stored on our servers)
• Communication data — enquiries, support tickets, WhatsApp/email/call records with our team
• Account data — login credentials (encrypted), order history, saved addresses
2.2 Information Collected Automatically
• IP address, device identifiers, browser type and version, operating system
• Pages visited, time spent, click patterns, referring/exit pages
• Approximate geolocation (derived from IP address)
• Cookies, web beacons, and similar tracking technologies (see Section 8)
2.3 Information from Third Parties
• Payment status from payment aggregators/gateways
• Delivery and shipment tracking from logistics/courier partners
• Aggregated analytics from Google Analytics, Google Search Console, and Meta/Instagram business tools
2.4 Sensitive Personal Data
We do NOT knowingly collect Aadhaar numbers, health records, biometric data, sexual orientation, or password-equivalent sensitive data beyond what is strictly necessary for account authentication (encrypted passwords). Where any SPDI (as defined in Section 1) is collected, it is collected only with your explicit consent and used strictly for the stated purpose.
3. Legal Basis and Purpose of Processing
In accordance with Section 4 of the DPDP Act, we process your personal data only for a lawful purpose for which you have given consent, or as otherwise permitted under law (e.g., for compliance with legal obligations, or in "legitimate uses" such as fulfilling a voluntarily provided order). Purposes include:
1. Processing, manufacturing (UV printing/personalization), and fulfilling orders
2. Generating GST-compliant invoices and maintaining statutory financial/tax records
3. Customer support, order tracking, and dispute resolution
4. Sending transactional communications (order confirmation, dispatch, delivery, refunds)
5. Sending promotional/marketing communications — only with your affirmative opt-in consent, with an easy opt-out in every communication
6. Improving Website functionality, product catalogue, and user experience
7. Fraud prevention, security monitoring, and abuse detection
8. Compliance with orders of a court, government agency, or applicable law
4. Consent
Wherever consent is the basis of processing, we will:
• Provide a clear notice, in plain language, describing the personal data to be collected and the purpose of processing, prior to or at the time of collection (Sec. 5, DPDP Act)
• Ensure consent is free, specific, informed, unconditional, and unambiguous, with a clear affirmative action
• Allow you to give, manage, review, or withdraw consent at any time, with the withdrawal process being as easy as giving consent
• Where you withdraw consent, we will cease processing within a reasonable time, except where retention is required by law (e.g., GST records)
5. How We Share Your Information
We do NOT sell or rent your personal data. We may share it, on a need-to-know basis and under contractual confidentiality obligations, with:
• Production & fulfilment partners — UV printing production units, packaging, and quality-check vendors
• Logistics partners — courier and delivery service providers, solely for shipment and delivery
• Payment processors — RBI-authorized/regulated payment gateway and aggregator partners
• Professional service providers — auditors, accountants, legal counsel
• Technology vendors — website hosting, cloud storage, analytics, and email/SMS/WhatsApp communication service providers
• Government and regulatory authorities — where required under law, judicial order, or to assist law enforcement/CERT-In directions
• Successors — in the event of a merger, acquisition, or sale of business or assets, with the acquiring entity bound to this Policy or an equivalent standard
Cross-Border Transfer
Where personal data is transferred outside India (e.g., cloud servers or SaaS tools hosted overseas), we ensure such transfer is to a jurisdiction not restricted by the Central Government under Section 16 of the DPDP Act, and that adequate contractual safeguards are in place.
6. Data Retention
We retain personal data only as long as necessary for the purpose for which it was collected, or as mandated under applicable law, including:
• Financial/GST records — as prescribed under the GST Act and Income Tax Act (currently a minimum of 6–8 years)
• Order and transaction data — for the limitation period applicable to consumer/contractual claims
• Marketing consent data — until you withdraw consent or request erasure
Upon expiry of the applicable retention period, or upon a valid erasure request (where no overriding legal obligation exists), personal data is securely deleted or anonymised.
7. Data Security
In compliance with Section 43A of the IT Act and Rule 8 of the SPDI Rules, we maintain reasonable security practices and procedures, including:
• Encryption of data in transit (SSL/TLS) and sensitive data at rest
• Access controls limiting data access to authorised personnel on a need-to-know basis
• Secure payment processing via PCI-DSS compliant gateway partners
• Regular security review of Website infrastructure
• Internal policies for incident response
Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and timeline prescribed under the DPDP Act and rules, and will comply with CERT-In's mandatory incident-reporting timelines (currently within 6 hours of noticing a reportable incident) where applicable.
No method of internet transmission or electronic storage is 100% secure; while we strive to protect your data, we cannot guarantee absolute security.
8. Cookies and Tracking Technologies
We use cookies and similar technologies for:
• Essential functions — login sessions, shopping cart persistence, checkout
• Analytics — understanding traffic and usage via tools such as Google Analytics
• Preferences — remembering display/language preferences
• Marketing (where applicable) — retargeting via Meta/Google ad platforms, only where permitted
You may control cookies through your browser settings, including blocking or deleting them. Disabling essential cookies may impair checkout and account functionality.
9. Your Rights as a Data Principal
Subject to the DPDP Act and applicable rules, you have the right to:
1. Right to Access — obtain a summary of personal data being processed and the processing activities undertaken
2. Right to Correction and Erasure — request correction of inaccurate/incomplete data, updating of data, or erasure of data no longer necessary for the stated purpose
3. Right to Grievance Redressal — register a grievance regarding processing of your data (Section 12)
4. Right to Nominate — nominate another individual to exercise your rights in the event of your death or incapacity
5. Right to Withdraw Consent — at any time, without affecting the lawfulness of processing prior to withdrawal
To exercise these rights, submit a request via the contact details in Section 12. We will respond within the timeline prescribed under applicable law.
10. Duties of Data Principals
In using the Website, you agree not to:
• Impersonate any person while furnishing personal data
• Suppress or fail to disclose material information relevant for the purpose of obtaining a good or service
• Register a false or frivolous grievance
11. Children's Data
Our products and Website are intended for use by individuals 18 years of age or older. Under the DPDP Act, a "child" means an individual under 18 years. We do not knowingly collect personal data of children without verifiable parental/guardian consent. If we become aware that a child's data has been collected without such consent, we will delete it promptly. Parents/guardians may contact us to request removal of a child's data.
12. Grievance Officer
In accordance with the Information Technology Act, 2000, the SPDI Rules, 2011, and the DPDP Act, 2023, the Grievance Officer / Contact Point for Magic Print Global LLP is:
Grievance Officer
Magic Print Global LLP
Pimpri, Pune, Maharashtra, India
Email: privacy@magicprint.in
Phone: +91 98504 44400 / +91 72762 51560
Working Hours: Monday–Saturday, 10:00 AM – 7:00 PM IST
We will acknowledge grievances promptly and resolve them within the timeline prescribed under applicable law (currently within 30 days of receipt, or as may be prescribed by the Data Protection Board of India).
13. Third-Party Links
The Website may link to third-party sites (e.g., social media, payment gateways). We are not responsible for the privacy practices of such third parties. Please review their respective privacy policies independently.
14. Changes to this Policy
We may revise this Privacy Policy periodically to reflect changes in law, regulation, or our business practices. Material changes will be notified via the Website or by email where appropriate. The "Last Updated" date reflects the most recent revision. Continued use of the Website after such changes constitutes acceptance of the revised Policy.
15. Governing Law and Jurisdiction
This Policy is governed by the laws of India. Courts at Pune, Maharashtra shall have exclusive jurisdiction over any disputes arising in connection with this Policy.
16. Contact Us
For any questions about this Privacy Policy or our data practices:
Magic Print Global LLP
Pimpri, Pune, Maharashtra, India
Website: www.magicprint.in
Email: privacy@magicprint.in
Phone: +91 98504 44400 / +91 72762 51560